Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-05T18:59:53.055489Z
Paper Citation Record · LEDGER
As of 19 August 2026, this Paper Citation Record lists 1 of 1 outbound references and 33 inbound Pith citation observations for arXiv:2508.14925.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-05T18:59:53.055489Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links, observed 2026-08-15T19:23:24.332483Z
A source-named dated measurement, never combined with another source.
Source: pith, observed 2026-08-05T02:28:24.338817Z
1 of 1 outbound references displayed
External citation measurements
0
pith, observed 2026-08-05T02:28:24.338817Z
Observation 74f68912-7c38-4f8f-9b1d-db5eb8c2db34 · outbound
MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 74f68912-7c38-4f8f-9b1d-db5eb8c2db34 · inbound
MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 63e9ffe8-108a-41c2-89b7-9223ea87983a · inbound
Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 280f776d-be11-4d24-ac11-78371288c7bd · inbound
MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5ad4840d-8d02-4b3b-84ab-d6e80204cc48 · inbound
Bridging Protocol and Production: Design Patterns for Deploying AI Agents with Model Context Protocol MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 4f6be4f1-d1b5-4026-ad19-0902aa710d67 · inbound
A Systematic Security Evaluation of OpenClaw and Its Variants MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation b2136d16-8ffc-47ea-b3c5-a8d0aefd8508 · inbound
ShieldNet: Network-Level Guardrails against Emerging Supply-Chain Injections in Agentic Systems MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation f07e0b5e-6a0b-4a0f-b2b8-b5390e8e0a91 · inbound
Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation e9743a8a-b306-4736-8a05-51ad514ae750 · inbound
A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 6de11461-dfc6-4a74-9244-8368755b80d4 · inbound
MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 5e074be1-2a67-4a94-a846-26556f984d7e · inbound
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 9089443f-c93e-48a5-8b0f-cda089c4f70e · inbound
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation a8b738dc-2e96-4193-a5ba-bbb4fcffa7e5 · inbound
CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 43b36547-6ae3-4f89-b79f-cf1cb2a10430 · inbound
Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation eafed71a-bbc8-4adf-8993-ad0ed76593c3 · inbound
Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 7a5c36b5-6d15-46e6-918c-a3bacf590c57 · inbound
Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 0bcc9a05-4e61-4fe2-be25-3c2f554c5d92 · inbound
Content-Aware Attack Detection in LLM Agent Tool-Call Traffic: An Empirical Study of Features, Architectures, and Evaluation Protocols MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation b57b6ff4-4735-4c6c-bd57-5309cd075be4 · inbound
Five Attacks on x402 Agentic Payment Protocol MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 134c0bd8-f035-4a6c-9a87-648ce23b9738 · inbound
From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 137
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation ed513a7c-7cfb-4e25-9757-4157bba206be · inbound
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation af80a512-1d00-4f55-a30f-11138deb5572 · inbound
Security, Privacy, and Ethical Risks in OpenClaw MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation cdb55672-5b6a-4da0-bf83-09e15e5a578a · inbound
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation d77bd3ab-780d-4b1e-be5d-e03684c2350f · inbound
Same Payload, Different Channel: Measuring Trust Asymmetry in Tool-Using Language Models MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 1
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 56855ef6-7237-4d8a-a0d3-cc662f613dfb · inbound
What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 30496f84-987f-4837-977d-f10af2c875f5 · inbound
Description-Code Inconsistency in Real-world MCP Servers: Measurement, Detection, and Security Implications MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 46979fa4-ae33-4eac-bec3-c99537fec36a · inbound
Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 8f8612d3-5e29-43fa-bafd-57e9560a459b · inbound
Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 0203a68e-7eb9-4579-a41c-4795d7cdbb4a · inbound
!Imperio, smolVLA: The Implications of Data Poisoning on Open Source Robotics MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation fe764729-0262-4633-9e61-773d06580b74 · inbound
Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.
Observation 055f4f6f-9039-42e0-9bd4-0ceebc8b5744 · inbound
Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 61
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3dd529ba-2ded-4228-b98c-d4a75e503ce7 · inbound
FlowGuard: From Signals to Evidence for MCP Security Detection MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7bc600cf-6912-4448-b7f8-232140c568e0 · inbound
CAGE: Certified Authorization under Typed-Return Uncertainty for Tool-Using Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c6000436-ab45-4b5b-9128-e2de2cc16494 · inbound
Persistent Semantic Entities in Tool-Augmented LLM Systems MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3130b42d-3d50-4847-af82-fc87021e75b9 · inbound
Beyond Handcrafted Security: Towards Self-Evolving Defense for LLM Agents MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
Reference 51
Source-reported events for the cited work
Unavailable: canonical work link unavailable.